CVE-2025-27038HIGH 7.5CISA KEVEPSS p51.9%

CVE-2025-27038Qualcomm Multiple Chipsets Use-After-Free Vulnerability

Qualcomm / Multiple Chipsets

Description

Multiple Qualcomm chipsets contain a use-after-free vulnerability. This vulnerability allows for memory corruption while rendering graphics using Adreno GPU drivers in Chrome.

Scoring

CVSS 3.17.5 (HIGH)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS0.80% probability of exploitation · percentile 51.9% · 2026-06-18T12:00:27Z
Published2025-06-03
Last modified2025-10-27

CISA KEV entry

Added to KEV: 2025-06-03

Underlying weaknesses· 1

CWE-416

References

  1. https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html
  2. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-27038

1

TypeTargetConfidenceTier
WeaknessUse After Freecwe-4160%live

(incoming)1

TypeTargetConfidenceTier
KEVEntryQualcomm Multiple Chipsets Use-After-Free Vulnerabilitykev-cve-2025-270380%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Qualcomm Multiple Chipsets Memory Corruption Vulnerability
CVE
Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability
CVE
Qualcomm Multiple Chipsets Integer Overflow Vulnerability
CVE
Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability
CVE
CVE-2025-1426
CVE
CVE-2025-14765
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.